Home / Technology / Wi-Fi Hacked: Hotels Become Spy Havens

Wi-Fi Hacked: Hotels Become Spy Havens

Summary

  • Hotels and conference centers are vulnerable to Wi-Fi spying campaigns.
  • Attackers use DNS poisoning to redirect users to fake login pages.
  • A VPN in full-tunnel mode is recommended for protection.
Wi-Fi Hacked: Hotels Become Spy Havens

A sophisticated spying campaign has been observed hijacking Wi-Fi networks in hotels and conference centers across multiple U.S. cities, as well as internationally in India and Saudi Arabia. This operation, active since at least June 2026, aims to steal user logins and authentication tokens by exploiting compromised Wi-Fi gateways.

The attackers manipulate the Domain Name System (DNS) through a technique called DNS poisoning. This redirects users attempting to access legitimate websites, such as Microsoft authentication portals, to fake, hacker-controlled pages. These malicious sites are designed to mimic official pages, tricking users into entering sensitive credentials.

While the exact method of gateway compromise remains unclear, it is suspected that attackers gained administrative access by targeting remote management interfaces, possibly exploiting weak or default passwords. This vulnerability allows hackers to intercept traffic from unsuspecting guests and conference attendees.

Cybersecurity experts suggest that the Russian state-sponsored hacking group FancyBear, also known as APT 28, may be behind this campaign due to similarities with previous attacks. However, some tradecraft observed, such as re-routing all DNS requests, could indicate a less sophisticated actor. This activity aligns with recent warnings from U.S. authorities about Russian hackers targeting vulnerable network devices.

To safeguard against these threats, travelers and attendees are strongly advised to use a VPN in full-tunnel mode on their devices. This encrypts all internet traffic, including DNS queries, effectively blocking potential snooping and mitigating the attack vector at its source by routing traffic through trusted corporate networks.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571